NIS2 Directive (EU) 2022/2555 is the EU’s cybersecurity law for organisations operating in critical sectors. It replaced the original NIS Directive and member states were required to transpose it into national law by 17 October 2024.

Two things distinguish NIS2 directive from what preceded it. The scope is far wider, covering eighteen sectors and capturing most medium and large organisations operating in them, with member states no longer having discretion to designate which entities are in scope.

Under NIS2 directive, the accountability is personal: Article 20 makes management bodies responsible for approving and overseeing cybersecurity measures, with liability for failure and, in serious cases, the possibility of temporary suspension from management functions.

NIS2 is a directive, not a regulation. It does not apply directly. Each member state transposes it into national law, and the national implementing law is what binds you. Several member states transposed late and infringement proceedings followed. The obligations described here are the NIS2 directive’s requirements; the operative detail sits in the national law of each member state where you operate.

NIS2 directive does not apply in the UK. The UK operates the NIS Regulations 2018, with the Cyber Security and Resilience Bill before Parliament to update them. UK organisations with EU operations are nonetheless in scope through those operations.

NIS2 Directive Key Definitions

TermDefinition
NIS2Network and Information Security Directive 2. Directive (EU) 2022/2555
NIS1The original Network and Information Security Directive (EU) 2016/1148, repealed 18 October 2024
Essential entityA large entity in an Annex I high-criticality sector, subject to proactive supervision
Important entityA medium entity in an Annex I sector, or a medium or large entity in an Annex II sector, subject to reactive supervision
Annex IHigh-criticality sectors: energy, transport, banking, financial market infrastructure, health, drinking water, wastewater, digital infrastructure, ICT service management, public administration, space
Annex IIOther critical sectors: postal and courier, waste management, chemicals, food, manufacturing, digital providers, research
Size-cap ruleThe threshold bringing medium and large entities into scope, with exceptions
CSIRTComputer Security Incident Response Team. The national body receiving incident notifications
Significant incidentAn incident meeting the Article 23(3) threshold, triggering mandatory reporting
Lex specialisA sector-specific law that displaces the general law. DORA operates this way for financial entities

What Does NIS2 Stand For

NIS2 stands for the second Network and Information Security Directive. The full title is Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union.

The abbreviation is written variously as NIS2, NIS 2, and NIS-2. All refer to the same instrument – NIS2 Directive.

What Is the NIS2 Directive

NIS2 establishes minimum cybersecurity requirements for organisations operating in sectors the EU considers critical to the functioning of society and the economy. It covers risk management, incident reporting, supply chain security, business continuity, and governance accountability.

NIS2 directive was adopted on 14 December 2022, published in the Official Journal on 27 December 2022, and entered into force on 16 January 2023. Member states had until 17 October 2024 to transpose it. NIS1 was repealed with effect from 18 October 2024.

NIS2 directive responded to three acknowledged failures in the original NIS regime. Scope was inconsistent because member states had discretion over which entities to designate, producing significant variation across the EU. Security requirements were vague enough that compliance was difficult to assess. And enforcement was weak, with penalties left largely to national discretion and rarely applied.

NIS2 addresses each. Scope is set by objective criteria rather than national designation. Article 21 lists ten specific measures organisations must implement. Article 34 sets penalty floors that member states must provide for.

Who Does NIS2 Directive Apply To

Scope turns on two questions: whether you operate in a listed sector, and whether you meet the size threshold.

The Sectors

Annex I: sectors of high criticality

SectorExamples of entities in scope
EnergyElectricity, district heating and cooling, oil, gas, hydrogen
TransportAir, rail, water, road
BankingCredit institutions
Financial market infrastructureTrading venues, central counterparties
HealthHealthcare providers, EU reference laboratories, medical device manufacturers producing critical devices, pharmaceutical manufacturers
Drinking waterSuppliers and distributors of water for human consumption
WastewaterUndertakings collecting, disposing of, or treating wastewater
Digital infrastructureInternet exchange points, DNS providers, TLD name registries, cloud computing providers, data centre providers, content delivery networks, trust service providers, electronic communications providers
ICT service managementManaged service providers, managed security service providers
Public administrationCentral government entities, and regional entities where designated
SpaceOperators of ground-based infrastructure supporting space services

Annex II: other critical sectors

SectorExamples of entities in scope
Postal and courier servicesPostal service providers, courier operators
Waste managementUndertakings carrying out waste management
ChemicalsManufacture, production, and distribution of chemicals
FoodProduction, processing, and distribution
ManufacturingMedical devices, computer and electronic products, electrical equipment, machinery, motor vehicles, other transport equipment
Digital providersOnline marketplaces, online search engines, social networking platforms
ResearchResearch organisations

The Size Threshold Under NIS2 Directive

The general rule brings medium-sized and large entities into scope. A medium-sized entity has at least 50 employees, or annual turnover and balance sheet total both exceeding €10 million. A large entity has at least 250 employees, or annual turnover exceeding €50 million and balance sheet total exceeding €43 million.

Certain entities are in scope regardless of size, including providers of public electronic communications networks, trust service providers, TLD name registries, DNS service providers, sole providers of a critical service in a member state, and entities whose disruption could have significant systemic risk.

Essential Versus Important

The classification determines the supervisory regime and the penalty ceiling, not the substantive obligations, which are identical.

FeatureEssential entityImportant entity
Typical basisLarge entity in an Annex I sectorMedium entity in Annex I, or medium or large in Annex II
SupervisionEx ante. Proactive inspections, regular audits, security scansEx post. Supervision triggered by evidence of non-compliance
Maximum fine€10 million or 2% of total worldwide annual turnover, whichever is higher€7 million or 1.4% of total worldwide annual turnover, whichever is higher
Article 21 measuresApply in fullApply in full
Article 23 reportingApplies in fullApplies in full
Management liabilityAppliesApplies

An important entity is not subject to lighter requirements. It is subject to lighter supervision until something goes wrong.

The Ten NIS2 Directive Article 21 Security Measures

Article 21 requires appropriate and proportionate technical, operational, and organisational measures to manage risks to network and information systems. Ten measures are named as the minimum.

#MeasureWhat it covers in practice
1Risk analysis and information system security policiesA documented risk assessment methodology and a security policy approved by management
2Incident handlingDetection, classification, response, and resolution processes, including the reporting workflow
3Business continuityBackup management, disaster recovery, crisis management, and tested restoration
4Supply chain securitySecurity of relationships with direct suppliers and service providers, including their security practices
5Security in acquisition, development, and maintenanceSecure development practices, vulnerability handling, and disclosure processes
6Effectiveness assessmentPolicies and procedures to assess whether the risk management measures actually work
7Cyber hygiene and trainingBasic hygiene practices and cybersecurity training across the organisation
8Cryptography and encryptionPolicies on the use of cryptography, and where appropriate encryption
9Human resources security, access control, asset managementPersonnel security, access policies, and an asset inventory
10Multi-factor authentication and secure communicationsMFA or continuous authentication, secured voice, video, and text communications, and secured emergency communications

Two of these deserve particular attention because they are where most organisations are furthest behind.

Supply chain security. Measure 4 requires you to account for the security posture of your direct suppliers. In practice this means supplier assessment before contracting, security requirements in supplier contracts, and a mechanism for identifying when a supplier’s compromise affects you. Organisations that have mapped their own systems but not their supplier dependencies have completed half the exercise.

Effectiveness assessment. Measure 6 requires you to test whether your controls work, not merely that they exist. A policy document that has never been exercised does not satisfy this.

Article 21 also requires an all-hazards approach. The measures address physical and environmental threats to systems as well as cyber threats.

Incident Reporting Under NIS2 Directive Article 23

Article 23 requires notification of any incident having a significant impact on the provision of services. The reporting process has three stages, with a fourth in some circumstances.

The Threshold

An incident is significant where it has caused or is capable of causing severe operational disruption of services or financial loss to the entity concerned, or where it has affected or is capable of affecting other natural or legal persons by causing considerable material or non-material damage.

The threshold is capability-based, not outcome-based. An incident that could have caused severe disruption is reportable whether or not it did.

The Clocks

StageDeadlineContent
Early warning24 hours from awarenessWhether the incident is suspected to be caused by unlawful or malicious acts, and whether it could have cross-border impact
Incident notification72 hours from awarenessUpdate to the early warning, initial assessment of severity and impact, and indicators of compromise where available
Intermediate reportOn requestStatus update where the competent authority or CSIRT asks for one
Final reportOne month from the incident notificationDetailed description, threat type and root cause, mitigation measures applied, and cross-border impact where applicable

Where an incident is ongoing at the one-month point, a progress report is submitted instead, with the final report due one month after the incident is handled.

Notifications go to the CSIRT or, where the member state has designated one, the competent authority. Where the incident has significant impact on service recipients, the entity must also inform them without undue delay.

The clocks run in elapsed hours from awareness, not from confirmation and not in working days.

NIS2 Directive Article 20: Management Liability

Article 20 is the provision that changed the internal politics of cybersecurity in scoped organisations.

Management bodies must approve the cybersecurity risk management measures, oversee their implementation, and can be held liable for the entity’s failure to comply. Members of management bodies are required to follow training, and entities are required to offer similar training to employees on a regular basis.

Article 32(6) goes further. Where an essential entity fails to comply and enforcement measures have proved ineffective, member state authorities may temporarily prohibit a person discharging managerial responsibilities at chief executive or legal representative level from exercising those functions.

This is a materially different accountability structure from GDPR, where liability attaches to the organisation. Under NIS2, cybersecurity failure is a board matter with personal consequences, and delegating it to IT is not a defence.

NIS2 Directive Penalties and Enforcement

Entity typeMaximum administrative fine
Essential entity€10 million or 2% of total worldwide annual turnover in the preceding financial year, whichever is higher
Important entity€7 million or 1.4% of total worldwide annual turnover in the preceding financial year, whichever is higher

Member states may set higher penalties. The directive sets a floor, not a ceiling.

Beyond fines, competent authorities have supervisory powers including on-site inspections, targeted security audits, security scans, requests for information and evidence of policy implementation, binding instructions and orders to remedy deficiencies, and orders to make public aspects of non-compliance.

The temporary management suspension power under Article 32(6) applies to essential entities only and is a measure of last resort after other enforcement has failed.

Does NIS2 Directive Apply to the UK?

No. NIS2 is an EU directive and the UK is not bound by it following Brexit.

The UK operates the Network and Information Systems Regulations 2018, which implemented NIS1 into UK law and remain in force. The Cyber Security and Resilience Bill, introduced in November 2025, updates that framework. It expands the scope of regulated entities, strengthens incident reporting duties, and brings managed service providers into the regime. It is the UK’s NIS2 analogue in policy terms, though it is a separate instrument with its own requirements.

UK organisations are nonetheless in scope of NIS2 in two circumstances.

Where a UK group has an EU establishment operating in a listed sector and meeting the size threshold, that EU entity is in scope of the national implementing law in its member state.

Where a UK entity provides services covered by the digital infrastructure or ICT service management categories to EU customers, jurisdiction may follow the main establishment rule in Article 26. For certain entity types including DNS providers, cloud computing providers, data centre providers, content delivery networks, and managed service providers, jurisdiction sits with the member state of main establishment in the EU, or where there is none, the member state where a representative is established. Entities in these categories with no EU establishment may be required to designate a representative in the EU.

ScenarioNIS2 applies
UK entity, UK operations onlyNo. UK NIS Regulations 2018 apply
UK parent with EU subsidiary in a listed sectorYes, to the EU subsidiary under national implementing law
UK managed service provider serving EU customersPotentially, through the Article 26 main establishment and representative rules
UK cloud provider with EU customers and no EU establishmentPotentially, with a requirement to designate an EU representative
UK manufacturer selling into the EU without EU operationsGenerally no under NIS2, though the CRA applies to products

Transposition Status of NIS2

NIS2 is a directive. It creates obligations for member states to legislate, not direct obligations on organisations. The national implementing law is what binds you.

Member states were required to transpose by 17 October 2024. A substantial number missed the deadline, and the Commission opened infringement proceedings against those that had not notified complete transposition.

The practical consequence is that obligations, thresholds, reporting channels, and penalty levels vary between member states in ways the directive does not fully harmonise. An organisation operating in several member states cannot assume one national implementation is representative of the others.

Areas where national variation is most likely include which authority receives incident notifications, whether the competent authority and CSIRT are the same body, registration and self-identification requirements, penalty levels above the directive floor, and the treatment of public administration entities at regional and local level.

NIS2 and Other EU Frameworks

DORA

Article 4 of NIS2 provides that where a sector-specific Union legal act requires entities to adopt cybersecurity risk management measures or notify significant incidents, and those requirements are at least equivalent in effect, the sector-specific provisions apply instead.

DORA is that act for financial entities. A bank, insurer, or investment firm in scope of DORA complies with DORA’s ICT risk management and incident reporting requirements rather than NIS2’s, for the matters DORA covers.

This is a displacement, not an exemption. The obligations are broadly comparable and DORA is more demanding in several respects, notably third-party risk management and threat-led penetration testing.

The Cyber Resilience Act

NIS2 regulates organisations. The CRA regulates products.

An organisation in scope of NIS2 that also manufactures products with digital elements faces both. NIS2 requires the organisation to manage cybersecurity risk in its own network and information systems. The CRA requires its products to be designed securely, to carry an SBOM, and to have vulnerability reporting through the ENISA Single Reporting Platform from 11 September 2026.

The incident reporting processes have similar operational shape but different triggers, deadlines, and recipients. NIS2 reporting concerns incidents affecting your service provision. CRA reporting concerns actively exploited vulnerabilities and severe incidents affecting your product’s security. Teams that built a NIS2 reporting flow have transferable process but not a substitute obligation.

The EU AI Act

Where an entity in scope of NIS2 deploys AI systems in its network and information systems, both frameworks apply to different aspects. NIS2 requires the systems supporting service provision to be secure. The AI Act imposes obligations on the AI system itself where it is high-risk, including Article 15 accuracy, robustness, and cybersecurity requirements.

An AI system used in the management of critical infrastructure is likely high-risk under Annex III of the AI Act and simultaneously part of the network and information systems NIS2 requires to be secured.

GDPR

A security incident involving personal data can trigger both NIS2 Article 23 reporting to the CSIRT and GDPR Article 33 reporting to the data protection authority. The thresholds differ, the recipients differ, and the deadlines differ, though both begin at 72 hours for the substantive notification. Neither notification discharges the other.

A NIS2 Compliance Checklist

StepAction
1Determine whether you operate in an Annex I or Annex II sector
2Apply the size threshold and identify whether you are an essential or important entity
3Identify every member state where you have an establishment in scope, and obtain the national implementing law for each
4Complete registration or self-identification where the national law requires it
5Conduct a documented risk assessment covering network and information systems
6Gap-assess against the ten Article 21 measures
7Map your supply chain and assess direct supplier security posture
8Establish the incident reporting process with the 24-hour, 72-hour, and one-month stages
9Identify the CSIRT or competent authority for each member state where you are in scope
10Secure management body approval of the risk management measures and record it
11Deliver management training and establish employee training on a recurring basis
12Implement effectiveness testing so that controls are exercised rather than only documented
13Establish business continuity and tested restoration procedures
14Reconcile with DORA, CRA, GDPR, and AI Act obligations where they also apply

What is NIS2?

NIS2 is Directive (EU) 2022/2555, the EU’s cybersecurity directive covering organisations in eighteen critical sectors. It establishes mandatory risk management measures, incident reporting obligations, supply chain security requirements, and management accountability. It replaced the original NIS Directive and member states were required to transpose it by 17 October 2024.

What does NIS2 stand for?

NIS2 directive is the second Network and Information Security Directive. The full title is Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union.

What does NIS2 apply to?

Entities operating in the sectors listed in Annex I and Annex II of the directive that meet the size threshold, generally medium and large organisations with at least 50 employees or turnover and balance sheet exceeding €10 million. Certain entity types are in scope regardless of size, including trust service providers, DNS providers, TLD registries, and sole providers of a critical service in a member state.

Does NIS2 apply to the UK?

No. NIS2 is EU law and does not bind the UK. The UK operates the NIS Regulations 2018, with the Cyber Security and Resilience Bill before Parliament to update them. UK organisations with EU establishments in scoped sectors are subject to NIS2 through those establishments, and UK providers of certain digital services to EU customers may fall within scope through the Article 26 jurisdiction rules.

What are the NIS2 requirements?

The core NIS2 directive’s requirements are the ten Article 21 risk management measures, the Article 23 incident reporting obligations with 24-hour, 72-hour, and one-month stages, and the Article 20 management accountability requirements including approval, oversight, liability, and training. National implementing laws may add registration and reporting detail.

What is the difference between essential and important entities under NIS2 directive?

The substantive obligations are identical. The difference is supervision and penalties. Essential entities face proactive supervision including regular audits and inspections, with fines up to €10 million or 2% of worldwide turnover. Important entities face reactive supervision triggered by evidence of non-compliance, with fines up to €7 million or 1.4%.

What are the NIS2 incident reporting deadlines?

An early warning within 24 hours of becoming aware of a significant incident, an incident notification within 72 hours, an intermediate report if the authority requests one, and a final report within one month of the incident notification. Where the incident is still ongoing at one month, a progress report is submitted and the final report follows one month after the incident is handled.

Can directors be personally liable under NIS2?

Yes. Article 20 makes management bodies responsible for approving and overseeing cybersecurity measures and provides that they can be held liable for the entity’s failure to comply. Article 32(6) allows authorities to temporarily prohibit a chief executive or legal representative of an essential entity from exercising managerial functions where other enforcement has proved ineffective.

Does NIS2 apply to us if we are a supplier to an in-scope organisation?

Not directly, unless you independently meet the sector and size criteria. However, Article 21 requires in-scope entities to manage supply chain security, which means your customers will impose security requirements, assessments, and contractual obligations on you. The effect is commercial rather than regulatory, and often just as binding.

How does NIS2 interact with DORA?

For financial entities in scope of both, DORA operates as lex specialis under Article 4 of NIS2. DORA’s ICT risk management and incident reporting requirements apply in place of the NIS2 equivalents for the matters DORA covers. Financial entities comply with DORA rather than duplicating under NIS2.

Is NIS2 a regulation or a directive?

A directive which means it does not apply directly. Each member state transposes it into national law, and the national implementing law is what creates binding obligations. This produces variation between member states in reporting channels, registration requirements, penalty levels, and scope detail.

What happens if our member state has not transposed NIS2?

Late transposition does not remove the obligation once national law arrives, and it does not delay it indefinitely. The Commission has opened infringement proceedings against member states that missed the October 2024 deadline. Organisations should build to the directive’s requirements and adjust to national detail as it is published, rather than waiting.

Disclaimer

This guide reflects Directive (EU) 2022/2555 and the status of national transposition as at September 2026. NIS2 is implemented through national law and the operative requirements in each member state are those of its implementing legislation. This guide is published by European Compliance Suite for general informational purposes and does not constitute legal advice. Organisations should obtain advice specific to their sector classification, size, and the member states in which they operate.

Fact Checked & Editorial Guidelines
Reviewed by: Subject Matter Experts